CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2026-42835

    Last Modified: 10 Jun 2026

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-42829

    Last Modified: 11 Jun 2026

    Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-42828

    Last Modified: 10 Jun 2026

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-40371

    Last Modified: 10 Jun 2026

    Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-33113

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    9.8
    Critical

    CVE-2026-26142

    Last Modified: 10 Jun 2026

    Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    6.5
    Medium

    CVE-2026-50508

    Last Modified: 10 Jun 2026

    Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-49161

    Last Modified: 10 Jun 2026

    Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-48583

    Last Modified: 10 Jun 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48578

    Last Modified: 8 Jul 2026

    Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48576

    Last Modified: 8 Jul 2026

    No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48575

    Last Modified: 10 Jun 2026

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48573

    Last Modified: 8 Jul 2026

    No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48570

    Last Modified: 10 Jun 2026

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-48568

    Last Modified: 10 Jun 2026

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-48566

    Last Modified: 14 Aug 2026

    Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-48563

    Last Modified: 8 Jul 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-47654

    Last Modified: 8 Jul 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    8.2
    High

    CVE-2026-47652

    Last Modified: 8 Jul 2026

    Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-47653

    Last Modified: 8 Jul 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-47648

    Last Modified: 10 Jun 2026

    Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-45588

    Last Modified: 11 Jun 2026

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-47641

    Last Modified: 8 Jul 2026

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47639

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-47638

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-47637

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47636

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-47635

    Last Modified: 8 Jul 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-41098

    Last Modified: 9 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    8.1
    High

    CVE-2026-47631

    Last Modified: 15 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    8
    High

    CVE-2026-47298

    Last Modified: 12 Jun 2026

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-32193

    Last Modified: 10 Jun 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-41092

    Last Modified: 15 Jun 2026

    Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-47292

    Last Modified: 15 Jun 2026

    Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    9.8
    Critical

    CVE-2026-47291

    Last Modified: 10 Jun 2026

    Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-47289

    Last Modified: 12 Jun 2026

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7.1
    High

    CVE-2026-47288

    Last Modified: 10 Jun 2026

    Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

    Published: 9 Jun 2026
    6.5
    Medium

    CVE-2026-47287

    Last Modified: 9 Jun 2026

    Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

    Published: 9 Jun 2026
    9.8
    Critical

    CVE-2026-45657

    Last Modified: 10 Jun 2026

    Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45656

    Last Modified: 15 Jun 2026

    Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    5.3
    Medium

    CVE-2026-45655

    Last Modified: 15 Jun 2026

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 9 Jun 2026
    4.3
    Medium

    CVE-2026-45650

    Last Modified: 10 Jun 2026

    User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.1
    High

    CVE-2026-45649

    Last Modified: 10 Jun 2026

    Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-45648

    Last Modified: 11 Jun 2026

    Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45645

    Last Modified: 8 Jul 2026

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45643

    Last Modified: 11 Jun 2026

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    3.9
    Low

    CVE-2026-45642

    Last Modified: 11 Jun 2026

    Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-45634

    Last Modified: 12 Jun 2026

    Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45641

    Last Modified: 8 Jul 2026

    Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45607

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026